8.8
CVSSv3

CVE-2018-1131

Published: 15/05/2018 Updated: 09/10/2019
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

Infinispan permits improper deserialization of trusted data via XML and JSON transcoders under certain server configurations. A user with authenticated access to the server could send a malicious object to a cache configured to accept certain types of objects, achieving code execution and possible further attacks. Versions 9.0.3.Final, 9.1.7.Final, 8.2.10.Final, 9.2.2.Final, 9.3.0.Alpha1 are believed to be affected.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

infinispan infinispan 9.3.0

infinispan infinispan 9.2.2

infinispan infinispan 8.2.10

infinispan infinispan 9.1.7

infinispan infinispan 9.0.3

redhat jboss data grid 7.2

Vendor Advisories

Synopsis Important: Red Hat JBoss Data Grid 721 security update Type/Severity Security Advisory: Important Topic An update for Red Hat JBoss Data Grid is now availableRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) base ...
Synopsis Important: Red Hat Fuse 750 security update Type/Severity Security Advisory: Important Topic A minor version update (from 74 to 75) is now available for Red Hat Fuse The purpose of this text-only errata is to inform you about the security issues fixed in this releaseRed Hat Product Security h ...
Infinispan permits improper deserialization of trusted data via XML and JSON transcoders under certain server configurations A user with authenticated access to the server could send a malicious object to a cache configured to accept certain types of objects, achieving code execution and possible further attacks Versions 903Final, 917Final, ...